| File name: | USBVaccine.zip |
| Full analysis: | https://app.any.run/tasks/8b53e140-26cb-46aa-9f32-2c3a4abf921d |
| Verdict: | Suspicious activity |
| Analysis date: | May 29, 2019, 07:33:58 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | C04609BA2C6D39813589479BAF819F62 |
| SHA1: | 28624AB7ABB5A71F39453A584C0CC20CB4D655AC |
| SHA256: | 105B6F281483353CB1451A404492381937E16F94505CFBA2257373FC3457D6E6 |
| SSDEEP: | 12288:D0W2SLaMucyRTaJMGi8q54cOGitSiUIW+aNF/PDOkf+nvZLkHGPFMygeEUg:12SLaHcyRmn2jOFtVOZ3gJkHGdMCg |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2009:10:23 13:02:17 |
| ZipCRC: | 0x908777f8 |
| ZipCompressedSize: | 823210 |
| ZipUncompressedSize: | 848856 |
| ZipFileName: | USBVaccineSetup.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 292 | "C:\Program Files\Panda USB Vaccine\USBVaccine.exe" /resident /autovaccinate /experimentalntfs /shownow | C:\Program Files\Panda USB Vaccine\USBVaccine.exe | USBVaccineSetup.tmp | ||||||||||||
User: admin Company: Panda Security Integrity Level: HIGH Description: USB Vaccine Exit code: 0 Version: 1.0.1.4 Modules
| |||||||||||||||
| 1380 | "schtasks.exe" /create /RU SYSTEM /TN PandaUSBVaccine /XML "C:\Users\admin\AppData\Local\Temp\is-30I4I.tmp\task.xml" | C:\Windows\system32\schtasks.exe | — | USBVaccineSetup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1832 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\USBVaccine.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2104 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1832.26334\USBVaccineSetup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1832.26334\USBVaccineSetup.exe | WinRAR.exe | ||||||||||||
User: admin Company: Panda Security Integrity Level: MEDIUM Description: Panda USB Vaccine Setup Exit code: 0 Version: 1.0.1.4 Modules
| |||||||||||||||
| 3076 | "C:\Users\admin\AppData\Local\Temp\is-LDPP4.tmp\USBVaccineSetup.tmp" /SL5="$40174,569893,52736,C:\Users\admin\AppData\Local\Temp\Rar$EXa1832.26334\USBVaccineSetup.exe" /SPAWNWND=$30176 /NOTIFYWND=$5014C | C:\Users\admin\AppData\Local\Temp\is-LDPP4.tmp\USBVaccineSetup.tmp | USBVaccineSetup.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.49.0.0 Modules
| |||||||||||||||
| 3252 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1832.26334\USBVaccineSetup.exe" /SPAWNWND=$30176 /NOTIFYWND=$5014C | C:\Users\admin\AppData\Local\Temp\Rar$EXa1832.26334\USBVaccineSetup.exe | USBVaccineSetup.tmp | ||||||||||||
User: admin Company: Panda Security Integrity Level: HIGH Description: Panda USB Vaccine Setup Exit code: 0 Version: 1.0.1.4 Modules
| |||||||||||||||
| 3268 | "schtasks.exe" /delete /TN PandaUSBVaccine /F | C:\Windows\system32\schtasks.exe | — | USBVaccineSetup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3440 | "C:\Users\admin\AppData\Local\Temp\is-NJ41G.tmp\USBVaccineSetup.tmp" /SL5="$5014C,569893,52736,C:\Users\admin\AppData\Local\Temp\Rar$EXa1832.26334\USBVaccineSetup.exe" | C:\Users\admin\AppData\Local\Temp\is-NJ41G.tmp\USBVaccineSetup.tmp | — | USBVaccineSetup.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.49.0.0 Modules
| |||||||||||||||
| (PID) Process: | (1832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1832) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\USBVaccine.zip | |||
| (PID) Process: | (1832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (1832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3076 | USBVaccineSetup.tmp | C:\Program Files\Panda USB Vaccine\is-4FHK8.tmp | — | |
MD5:— | SHA256:— | |||
| 3076 | USBVaccineSetup.tmp | C:\Program Files\Panda USB Vaccine\is-EQV0S.tmp | — | |
MD5:— | SHA256:— | |||
| 3076 | USBVaccineSetup.tmp | C:\Program Files\Panda USB Vaccine\is-3SPNA.tmp | — | |
MD5:— | SHA256:— | |||
| 3076 | USBVaccineSetup.tmp | C:\Program Files\Panda USB Vaccine\unins000.exe | executable | |
MD5:— | SHA256:— | |||
| 292 | USBVaccine.exe | C:\ProgramData\Panda Security\USB Vaccine\Update.ini | html | |
MD5:— | SHA256:— | |||
| 3076 | USBVaccineSetup.tmp | C:\Program Files\Panda USB Vaccine\RunInteractiveWin.exe | executable | |
MD5:— | SHA256:— | |||
| 3076 | USBVaccineSetup.tmp | C:\Users\admin\AppData\Local\Temp\is-30I4I.tmp\_isetup\_shfoldr.dll | executable | |
MD5:92DC6EF532FBB4A5C3201469A5B5EB63 | SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87 | |||
| 3076 | USBVaccineSetup.tmp | C:\Users\admin\AppData\Local\Temp\is-30I4I.tmp\task.xml | xml | |
MD5:— | SHA256:— | |||
| 3076 | USBVaccineSetup.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security\Panda USB Vaccine\Uninstall Panda USB Vaccine.lnk | lnk | |
MD5:— | SHA256:— | |||
| 3076 | USBVaccineSetup.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security\Panda USB Vaccine\Panda USB Vaccine on the Web.url | text | |
MD5:9DABE20BD327B01973AFD09756AC93DE | SHA256:D6236D38C0D44E513222B014B306B008990855BAFE770B7EA10AA0526EB1D1DA | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
292 | USBVaccine.exe | GET | 404 | 172.217.21.212:80 | http://vaccineusbstat.appspot.com/getlastversion?MUID=4c1540f0-625d-4b2e-8aa4-a848b4760137&version=1.0.1.4 | US | html | 1.51 Kb | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
292 | USBVaccine.exe | 172.217.21.212:80 | vaccineusbstat.appspot.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
vaccineusbstat.appspot.com |
| suspicious |